{ "id": "CVE-2005-1064", "sourceIdentifier": "cve@mitre.org", "published": "2005-04-10T04:00:00.000", "lastModified": "2016-10-18T03:17:01.527", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 4.6 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 3.9, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:rsnapshot:filesystem_snapshot_utility:1.0.10:*:*:*:*:*:*:*", "matchCriteriaId": "5E29213B-F98C-41EE-9275-7EEF1AB75FC9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:rsnapshot:filesystem_snapshot_utility:1.1:*:*:*:*:*:*:*", "matchCriteriaId": "B817B1C1-6E0D-4F78-94C0-40DE119C8A18" }, { "vulnerable": true, "criteria": "cpe:2.3:a:rsnapshot:filesystem_snapshot_utility:1.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "AA84172D-BDA2-4390-84C5-C34D848E263D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:rsnapshot:filesystem_snapshot_utility:1.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "E175E2DF-8DC6-4207-8292-8D457779B732" }, { "vulnerable": true, "criteria": "cpe:2.3:a:rsnapshot:filesystem_snapshot_utility:1.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "DBB950ED-A563-4F3D-AE9C-C51F1298FE2B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:rsnapshot:filesystem_snapshot_utility:1.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "5DF21126-D66C-40CD-BB41-B4314EFF35A7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:rsnapshot:filesystem_snapshot_utility:1.1.5:*:*:*:*:*:*:*", "matchCriteriaId": "4CC58B7B-F546-4731-AF8D-11E4E0F50777" }, { "vulnerable": true, "criteria": "cpe:2.3:a:rsnapshot:filesystem_snapshot_utility:1.1.6:*:*:*:*:*:*:*", "matchCriteriaId": "F56E553F-78A7-4F77-BF25-342AF722CB36" }, { "vulnerable": true, "criteria": "cpe:2.3:a:rsnapshot:filesystem_snapshot_utility:1.2:*:*:*:*:*:*:*", "matchCriteriaId": "1A49462C-E253-4067-A099-5FD06D362587" } ] } ] } ], "references": [ { "url": "http://marc.info/?l=full-disclosure&m=111317179531000&w=2", "source": "cve@mitre.org" }, { "url": "http://securitytracker.com/id?1013674", "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://www.gentoo.org/security/en/glsa/glsa-200504-12.xml", "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://www.rsnapshot.org/security/2005/001.html", "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ] } ] }